A suspected member of the ShinyHunters digital extortion group, who goes by the online alias “Rey,” has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter.
Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and law enforcement to identify other members of the group.
“His cooperation is critical to ongoing efforts to arrest these hackers,” a source told the news agency.
Rey, who also went by the online alias ReyXBF, is not an unknown face. In a report published in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of Scattered LAPSUS$ Hunters (SLH or SLSH), a group that’s assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters.
“Previously, Rey was an administrator of the data leak website for Hellcat, a ransomware group that surfaced in late 2024,” Krebs noted at the time. “Also in 2024, Rey would take over as administrator of the most recent incarnation of BreachForums.” Khader also told Krebs that he had been cooperating with law enforcement since at least June 2025.
The development is the latest action in the ShinyHunters saga, which also saw the arrest of a 24-year-old Amsterdam man last week for their involvement in the threat actor’s malicious cyber operations.
Although his identity has not been disclosed, independent reports revealed that it was Pepijn van der Stap, a reformed hacker who has been employed as an offensive security lead at the Dutch company Neo Security. A ShinyHunters spokesperson subsequently denied having any connections with van der Stap.
Following the arrest, FBI director Kash Patel said, “FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest.” In a follow-up X post, Patel said, “FBI teams are working new leads RIGHT NOW. More arrests are on the table.”
ShinyHunters insisted that it’s not seeking a monetary payoff in the FBI case, but rather apply pressure on the FBI to amend what it said were false allegations about the group and challenge claims made by the agency about its connections with The Com, a loose-knitcybercrime collective notorious for social engineering, phishing, SIM swapping, extortion, sextortion, swatting, kidnapping, and physical violence.
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a recorded statement. “They often target third-party vendors in cloud-based platforms, stealing sensitive data and extort victims with threats to publish it.”
Leatherman, who described van der Stap as an alleged leader of the group, also urged other members to speak out and said that they can no longer hide behind perceived international anonymity and evade detection.
“Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you,” Leatherman added. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
In a deep-dive report tracing ShinyHunters’ origins and their tactical evolution, cybersecurity companies Sekoia and Beazley Security said its lineage goes back to two progenitor hacking groups, TheDarkOverlord and GnosticPlayers, that specialized in extortion and data leak operations. The ShinyHunters brand emerged publicly around April or May 2020.
“Six years on, ShinyHunters is less a group than a brand and business model that has outlived its founders,” researchers Enzo Saez and Robert (Bobby) Venal said. “What began in 2020 as a small crew trading stolen databases on RaidForums has become a persistent, self-renewing group that has absorbed indictments, arrests, and forum seizures without ever going quiet for long.”
“That resilience is the real story. It doesn’t come from any single leader or cell, but from a division of labor that has become almost modular: initial access from social engineers, amplification and recruitment from adjacent actors, and monetization under a shared, recognizable brand.”
📰 Original Source:TheHackerNews ✍️ Author: info@thehackernews.com (The Hacker News)
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Leave a Reply